cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1151
Views
0
Helpful
6
Replies

ace tcp idle timer VERY URGENT!

KAROLY KOHEGYI
Level 2
Level 2

Hi,

I set the following

parametermap type conection TCP-60sec

set timeout inactivity 60

policy-map multi match Tandem

class POS-33067

loadbalance vip inservice

loadbalance policy POS-33067

loadbalance vip icmp-reply

loadbalance vip advertise

connection advanced-options TCP-60sec

interface vlan 100

service-policy input Tandem

Unfurtunetly this is not affect. after clear conn there will be connections which have more than 60 sec idle timeout.

Very thanks

6 Replies 6

Surya ARBY
Level 4
Level 4

remove and reapply your service policy on the vlan interface ?

Hi,

i did not !

Is it needed or a idea?

Thanks,

I'm not the devloper of the box

I've always believed that it would reprogram some parts of the data plane.

Daniel Arrondo Ostiz
Cisco Employee
Cisco Employee

Hi Karoly,

Please take into account that, as long as one of the sides of the connection (client-to-ace or ace-to-server) is still open, the other one will remain open as well even if the inactivity timeout is higher than what it's configured. This could happen if, for example, one of the sides is using TCP keepalives but the other one is not.

This is just something to check to see if you really have an issue or not. If you need further troubleshooting, I would recommend you to open a TAC case.

Regards

Daniel

Thanks Daniel,

there are no keepalives. ace-to-server session was closed and ace-to-client was ESTABLISHED state.

The idle time more than 60sec in both.

The client initiated one connection and server closed it with FIN, but client send RST w/o FIN,ACK.

I do not understand why does not   the RST packet closed the ACE sessions??

Hi Karoly,

I'm afraid I cannot give you a straight answer. Please, open a TAC case and we will have a deeper look into it.

Daniel